Trojan

Trojan.Miuref information

Malware Removal

The Trojan.Miuref is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Miuref virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates a hidden or system file
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

edgedl.me.gvt1.com

How to determine Trojan.Miuref?


File Info:

crc32: C767EEB4
md5: 515941cdc63b0015fe9b8dcd99e175e7
name: 515941CDC63B0015FE9B8DCD99E175E7.mlw
sha1: f0d9284c3d44f7d2c3f3cd0f7b5da13bd917c8ec
sha256: b5a71b0ae0674e0232cc1be8e4f17122c4dcc28e2e29da126248a37e223bd57c
sha512: 1675fdfd0d90effc07680374ca9519de056b939c085adf4afbfb15ae02bc415e6023a8abadf11609a0595e1207b6914ff1635bbc6762740606f9c79783f0ed69
ssdeep: 6144:UNjAZOiPFeoJipVP3ARnq3srwz/kG2JVkXgo5hVwPaCtiremZ:kMjEoJiPAC+FjigIIPBirr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2005-2012 Oleg N. Scherbakov
InternalName: 7ZSfxMod
FileVersion: 1.5.0.2712
CompanyName: Oleg N. Scherbakov
PrivateBuild: December 30, 2012
ProductName: 7-Zip SFX
ProductVersion: 1.5.0.2712
FileDescription: 7z Setup SFX (x86)
OriginalFilename: 7ZSfxMod_x86.exe
Translation: 0x0000 0x04b0

Trojan.Miuref also known as:

K7AntiVirusTrojan ( 005224381 )
LionicTrojan.Win32.Inject.4!c
DrWebTrojan.Boaxxe.484
CynetMalicious (score: 99)
CAT-QuickHealRansom.Cerber.A4
ALYacGen:Variant.Ransom.Seven.18
CylanceUnsafe
K7GWTrojan ( 005224381 )
Cybereasonmalicious.dc63b0
CyrenW32/S-3e1d46f2!Eldorado
SymantecTrojan.Gen
ESET-NOD32multiple detections
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Bunitu-7394346-1
KasperskyUDS:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Inject.egzjpm
MicroWorld-eScanTrojan.Ransom.Cerber.1
TencentWin32.Trojan.Yakes.Stan
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34170.oq1@aa@v2ae
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCERBER.SM3
McAfee-GW-EditionPWSZbot-FAVD!834F4493F82E
FireEyeGeneric.mg.515941cdc63b0015
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Malicious SFX
JiangminBackdoor.Hlux.bol
AviraTR/Crypt.ZPACK.ezvcr
eGambitUnsafe.AI_Score_97%
Antiy-AVLTrojan/Generic.ASMalwS.1BA5BA6
MicrosoftTrojan:Win32/Miuref.R
ArcabitTrojan.Ransom.Cerber.1
ZoneAlarmTrojan.Win32.Menti.gen
GDataGen:Variant.Ransom.Seven.18
McAfeeArtemis!515941CDC63B
MAXmalware (ai score=83)
VBA32Trojan.Miuref
MalwarebytesSpyware.Boaxxe
PandaTrj/CI.A
TrendMicro-HouseCallRansom_HPCERBER.SM3
YandexTrojan.Yakes!5iFdOe+OMxI
IkarusTrojan.Win32.Boaxxe
FortinetW32/Kryptik.HGZD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Miuref?

Trojan.Miuref removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment